Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Tmarkettos

#32294of 53,630
7.8Total CVSS
Vulnerabilities · 1
PT-2024-4011
7.8
2024-02-18
Less · Less · CVE-2022-48624
Name of the Vulnerable Software and Affected Versions: less versions prior to 606 Description: The issue is related to the close altfile function in filename.c, which omits shell quote calls for LESSCLOSE. This can allow an attacker to execute arbitrary commands. Recommendations: For versions prior to 606, update to version 606 or later to resolve the issue. As a temporary workaround, consider restricting the use of the LESSCLOSE variable to minimize the risk of exploitation.